SSO OneLogin

This article describes how to integrate OneLogin with Umbrella.

How To Integrate OneLogin

  1. Access your OneLogin developer account.
  2. On the Administration page, go to Applications > Add App.
  3. Find the AWS Cognito.
  4. Set Umbrella (SAML) under the Display name (or any other name).
  5. Add an icon and description (optional).
  6. Click Save.
  7. Go to Applications > Umbrella (SAML) > Configuration and enter the following:
    • In SAML Audience, set: urn:amazon:cognito:sp:us-east-1\_Uv6ArNdSK
    • In ACS (Consumer) URL, set the same: https\://mypileus.auth.us-east-1.amazoncognito.com/saml2/idpresponse
    • In ACS (Consumer) URL Validator, set: https\://mypileus.auth.us-east-1.amazoncognito.com/saml2/idpresponse
    • In the Single Logout URL, set: https\://mypileus.io/log\_out
  8. Click Save.
  9. Go to Applications > Umbrella (SAML) > Users.
  10. Add the relevant users.
  11. Forward to Umbrella support the following to complete the configuration on Umbrella's side ([email protected]):
    • Issuer URL (go to Applications > Umbrella (SAML) > SSO > Issuer URL)
    • A list of all email domains
  12. After Umbrella completes the integration, we will provide you the URL value, please enter it in OneLogin at:
    • Go to Applications > Umbrella (SAML) > Configuration
    • at the Login URL set the URL you received from Umbrella.

As part of the SSO integration, follow the steps below to add users and management roles from the IDP (identity provider):

  1. Navigate to the Applications > Umbrella (SAML) > Parameters.
  2. Click on "+" icon.
  3. Define the New field as follows and click on Save:
  1. Navigate to the Applications > Umbrella (SAML) > Rules.
  2. Click on Add Rule.
  3. Define the condition based on your roles.
  4. Under the Actions section, define the following:

ℹ️

you can find the role ID of a specific role on the Accounts > Roles & Users page.